Holy Cow Studios

Holy Cow Studios

Privacy Policy

Privacy Policy

How we handle personal data, protect your choices, and keep our commitments clear.

How we handle personal data, protect your choices, and keep our commitments clear.

Effective 21 August 2026

Effective 21 August 2026

•

Last updated 21 August 2026

Last updated 21 August 2026

Privacy Policy

Effective date: 21 August 2026 Last updated: 21 August 2026

Holy Cow Studios Private Limited (“Holy Cow Studios”, “we”, “us”, “our”) respects your privacy. This policy explains what personal data we handle, why, who we share it with, how long we keep it, and the rights you have over it.

We have written it to be read, not to be survived. If anything here is unclear, write to us and we will explain it in plain terms.

1. Who we are

Holy Cow Studios Private Limited is the data controller — under India’s Digital Personal Data Protection Act, 2023, the Data Fiduciary — for the personal data described in Part I of this policy.

Grievance Officer

We acknowledge every request promptly and respond within 30 days. That 30-day period runs from when you contact us, not from the next working day — the hours above tell you when someone is at a desk, not when your request starts counting.

2. Scope, and the two different roles we play

This policy covers holycowstudios.in, www.holycowstudios.in, research.holycowstudios.in, our correspondence with you, and participation in our research programmes including the Goa AI Readiness Benchmark.

We handle personal data in two quite different capacities, and your rights differ depending on which applies.

This distinction is not a technicality. When we build an automation for a hotel, the guest data flowing through it belongs to that hotel’s relationship with its guests, not to ours.

This policy does not cover third-party websites we link to. Those have their own policies and we do not control them.

Part I — Data we control

I.1 What we collect, and why

Information you give us

Under the DPDP Act, our lawful ground for each of the above is your consent, given when you choose to submit the information, except where we may process it for the legitimate use of responding to a request you made.

We do not sell personal data. We have never sold personal data. We do not share it for cross-context behavioural advertising.

Information collected automatically

When you visit, we and our providers may record your IP address, browser and device type, referring page, the pages you view, and the dates and times of those visits. This keeps the site working and tells us which research is read. What is stored on your device, and when, is set out in §I.3.

What we do not collect

We do not knowingly collect special-category data — health, biometrics, religious or political views, sexual orientation, or trade-union membership. We do not ask for payment-card details on this website. Please do not send us any of these.

I.2 Our research programme

This section applies if you take part in our research, including the Goa AI Readiness Benchmark. It is a public statement of commitments we hold ourselves to, not boilerplate.

What we collect. Your name, role, employer, contact details and what you tell us in interviews. We also record publicly observable facts about the property or business — published rates, response times, website structure and similar — which we gather without needing your cooperation.

Our commitments.

  1. Findings are published only in aggregate and anonymised. No property and no

individual is identified in any published report without separate, written permission.

  1. Your individual results are confidential and are never shown to a competitor.

Your data belongs to the conversation we had, not to our sales pipeline.

  1. Every audited property receives its own results free and unconditionally,

whether or not it ever becomes a client, and whether or not it wants anything further from us.

  1. You may withdraw at any time, before or after publication, and we will remove

your data from the dataset. Where a finding has already been published in aggregate form and cannot be disentangled, we will tell you so plainly rather than imply otherwise.

  1. Participation is not conditional on buying anything. Declining to buy has no

effect on what you receive.

Legal basis. Consent, which you may withdraw at any time by writing to the Grievance Officer. Where we record only publicly available information about a business, we rely on legitimate interests in conducting research.

I.3 Cookies and similar technologies

Strictly necessary cookies keep the site working. They cannot be switched off and are set without consent, as the law permits.

Analytics cookies (Google Analytics 4, loaded through Google Tag Manager) tell us which pages and papers are read. What happens depends on where you are, and we would rather state that plainly than imply a single rule:

We use Google Consent Mode, so your choice is passed to Google directly and applies from the moment you make it. Withdrawing consent is as easy as giving it, and takes effect immediately.

Our research papers set no analytics cookies at all. On research.holycowstudios.in, wherever you are in the world, measurement is cookieless: we can see that a page was viewed and roughly where from, but nothing is stored on your device, nothing identifies you, and one visit cannot be linked to another.

We use no advertising, marketing or profiling cookies anywhere, in any region. Advertising storage is switched off by default and we have never switched it on.

Your browser can also block or delete cookies. Doing so may stop parts of the site working.

I.4 Who we share it with

We share personal data only with providers who process it on our instructions, and only as far as they need it to do their job.

We may also disclose personal data where we are legally required to — to a court, regulator or law-enforcement authority acting under proper authority — or to establish or defend legal claims. If we are ever compelled to disclose your data, we will tell you unless we are legally prohibited from doing so.

I.5 International transfers

We are based in India. Some providers above are in the United States or the European Union, so your personal data may be transferred outside your country.

Where data protected by the GDPR or UK GDPR is transferred outside the UK or EEA, we rely on the European Commission’s Standard Contractual Clauses, or on an adequacy decision where one applies. You may request a copy of the safeguards we rely on by writing to the Grievance Officer.

I.6 How long we keep it

When a period ends we delete the data or irreversibly anonymise it.

Part II — Data we process on behalf of clients

When we build, run or support an automation, an AI system or an IT service for a client, personal data may pass through it — the client’s customers, guests, staff or suppliers.

For that data, the client is the controller and we are the processor. We act only on the client’s documented instructions, under a written contract or data processing agreement.

What that means in practice:

  • We do not decide what that data is used for. The client does.

  • We do not use it for our own purposes — not for research, not for marketing,

not for training any AI model, not for our benchmarks or case studies. Where we publish a case study, it is agreed in writing with the client first and contains no personal data.

  • We keep it only as long as the engagement requires, then return or delete it as

the client instructs.

  • We apply the same security measures described in §III.3.

  • If we engage a sub-processor, we do so only where the client’s contract permits

and under equivalent obligations.

If you are a customer of one of our clients and want to exercise rights over your data, please contact that organisation — they are the controller and hold the relationship with you. If you contact us instead, we will pass your request on promptly and tell you we have done so, but we cannot act on it directly without the client’s instruction. This is a legal constraint, not an unwillingness to help.

Part III — General

III.1 Your rights

Wherever you live, you may ask us to:

  • Tell you what personal data we hold about you, and give you a copy

  • Correct anything inaccurate or incomplete

  • Delete it, where there is no overriding reason for us to keep it

  • Restrict or object to how we use it

  • Port it to another provider in a machine-readable form

  • Withdraw consent at any time, without affecting anything done before you

withdrew it

Depending on where you live you may also have the right to:

  • India (DPDP Act 2023): nominate another person to exercise these rights on

your behalf if you die or become incapacitated; use our grievance redressal process before approaching the Data Protection Board of India; and, where we make consent available through a registered Consent Manager, to give, manage, review and withdraw your consent through that Consent Manager

  • EEA / UK (GDPR): complain to your data protection authority

  • California (CCPA/CPRA): know, delete, correct, and opt out of sale or sharing —

we do not sell or share personal data, so there is nothing to opt out of — and not be discriminated against for exercising these rights

How to exercise them. Write to gaurav.hooda@holycowstudios.in. We respond within 30 days. We may ask you to confirm your identity first — not to obstruct you, but because handing your data to someone impersonating you would be a worse failure than a delay. Exercising these rights is free.

III.2 Automated decision-making

We do not make decisions about you by automated means that produce legal effects or similarly significant effects.

We advise clients on artificial intelligence, and we use AI tools in preparing our own research and written material. Those tools are not used to make decisions about individuals, and personal data you give us is not used to train any third-party AI model.

III.3 Security

We use HTTPS across all our sites, restrict access to personal data to people who need it, and choose providers who maintain recognised security practices. These are reasonable security safeguards appropriate to the data we hold; they are not a guarantee.

No system is perfectly secure, and anyone who tells you otherwise is selling something. If we become aware of a breach affecting your personal data, we will notify you and the relevant authority as the law requires — under the DPDP Act, the Data Protection Board of India, and under the GDPR, within 72 hours where the breach is likely to result in a risk to your rights.

III.4 Children

Our services are for businesses and are not directed at children. Under the DPDP Act, a child is anyone under 18. We do not knowingly collect personal data from anyone under 18, we do not knowingly track or behaviourally monitor children, and we do not direct advertising at them. If you believe a child has given us personal data, tell us and we will delete it.

III.5 Other websites, widgets and anything you post publicly

Links. Our sites link to other organisations’ websites. We do not control them and are not responsible for their content or their privacy practices. Check their policies before giving them your data.

Social media links and widgets. Where our site links to or embeds LinkedIn, WhatsApp, X or similar, your interaction with those is governed by that company’s privacy policy, not ours.

Anything you post publicly. If you post a comment, review or message in a public place — including our social media pages — it can be read, copied and used by others. We are not responsible for personal information you choose to disclose publicly.

III.6 Do Not Track and Global Privacy Control

There is no single agreed standard for “Do Not Track” browser signals, and we do not currently respond to them. We do honour the Cookie Settings choice you make on this site, which is the control that actually governs what we collect.

III.7 Business transfers

If our business is sold or reorganised, personal data may transfer to the acquirer, who will remain bound by this policy until you are told otherwise.

III.8 Language

This policy is published in English. On request to the Grievance Officer, we will provide it in any language listed in the Eighth Schedule to the Constitution of India.

III.9 Changes to this policy

We may update this policy. The effective date at the top always shows the current version. If we make a change that materially affects your rights, we will say so prominently on this page and notify subscribers by email. We will not apply a materially different use of data you have already given us without asking you again.

III.10 Governing law

This policy is governed by the laws of India, and the courts at Karnal, Haryana have jurisdiction. This does not remove any right you have to bring a claim, or complain to a regulator, in the country where you live.

III.11 Complaints

Please raise any concern with our Grievance Officer first — we would rather fix it than have you escalate.

If you are not satisfied, you may complain to:

  • India: the Data Protection Board of India

  • EEA: the supervisory authority in your country of residence or work

  • UK: the Information Commissioner’s Office

III.12 Contact

Gaurav Hooda, Grievance Officer Holy Cow Studios Private Limited gaurav.hooda@holycowstudios.in Sector 32 Park 3, First Floor, House No 13, Unnamed Road, Sector 32, Karnal, Haryana 132001, India +91 9311421200

·

Legal name: Holy Cow Studios Private Limited

CIN: U72900DL2021PTC378100

Registered office: Sector 32 Park 3, First Floor, House No 13, Unnamed Road, Sector 32, Karnal, Haryana 132001, India

Operations: Next to Magsons Supercentre, Dayanand Bandodkar Marg, Miramar, Panaji, Goa 403001, India

Email: office@holycowstudios.in

Telephone: +91 9311421200

·

Name: Gaurav Hooda

Designation: Grievance Officer

Email: gaurav.hooda@holycowstudios.in, or office@holycowstudios.in

Postal address: Sector 32 Park 3, First Floor, House No 13, Unnamed Road, Sector 32, Karnal, Haryana 132001, India

Working hours: Monday to Friday, 10:00–18:00 IST, excluding public holidays

· Part I — data we control · Part II — data we process for a client

Whose data: Website visitors, enquirers, subscribers, research participants Our client’s customers, staff or contacts

Our role: Data Fiduciary / controller — we decide why and how Data Processor — we act only on the client’s documented instructions

Who you ask about your rights: Us The client, who is the controller. We will pass on any request we receive

What · When · Why · Legal basis (GDPR)

Name, email, phone, message: You submit the contact form To answer you Legitimate interests / steps prior to a contract

Email address: You subscribe to updates To send you research and updates Consent

Name, email, meeting details: You book a call To hold the meeting Steps prior to a contract

Correspondence and notes: You contact us To maintain a record of our dealings Legitimate interests

Where you are · What we do

European Economic Area and the United Kingdom: Analytics are off until you accept. Nothing is stored on your device before you choose

Everywhere else, including India: Analytics are on by default. You can switch them off at any time using Cookie Settings in the footer

Provider · What they do · Where

Framer B.V.: Hosts and serves this website Netherlands / EU

Google LLC: Google Analytics 4, Google Tag Manager, Google Fonts United States

Cal.com, Inc.: Meeting scheduling United States

Hostinger International Ltd: Email, and hosting for research.holycowstudios.in Lithuania / EU

Data · Retention

Contact-form enquiries that do not become client relationships: 24 months from last contact

Newsletter subscribers: Until you unsubscribe, plus 12 months

Client records: 8 years after the engagement ends, for tax and statutory purposes

Research programme data: Until the study is published, plus 36 months, to allow findings to be checked

Website analytics: 14 months

Privacy Policy

Effective date: 21 August 2026 Last updated: 21 August 2026

Holy Cow Studios Private Limited (“Holy Cow Studios”, “we”, “us”, “our”) respects your privacy. This policy explains what personal data we handle, why, who we share it with, how long we keep it, and the rights you have over it.

We have written it to be read, not to be survived. If anything here is unclear, write to us and we will explain it in plain terms.

1. Who we are

Holy Cow Studios Private Limited is the data controller — under India’s Digital Personal Data Protection Act, 2023, the Data Fiduciary — for the personal data described in Part I of this policy.

Grievance Officer

We acknowledge every request promptly and respond within 30 days. That 30-day period runs from when you contact us, not from the next working day — the hours above tell you when someone is at a desk, not when your request starts counting.

2. Scope, and the two different roles we play

This policy covers holycowstudios.in, www.holycowstudios.in, research.holycowstudios.in, our correspondence with you, and participation in our research programmes including the Goa AI Readiness Benchmark.

We handle personal data in two quite different capacities, and your rights differ depending on which applies.

This distinction is not a technicality. When we build an automation for a hotel, the guest data flowing through it belongs to that hotel’s relationship with its guests, not to ours.

This policy does not cover third-party websites we link to. Those have their own policies and we do not control them.

Part I — Data we control

I.1 What we collect, and why

Information you give us

Under the DPDP Act, our lawful ground for each of the above is your consent, given when you choose to submit the information, except where we may process it for the legitimate use of responding to a request you made.

We do not sell personal data. We have never sold personal data. We do not share it for cross-context behavioural advertising.

Information collected automatically

When you visit, we and our providers may record your IP address, browser and device type, referring page, the pages you view, and the dates and times of those visits. This keeps the site working and tells us which research is read. What is stored on your device, and when, is set out in §I.3.

What we do not collect

We do not knowingly collect special-category data — health, biometrics, religious or political views, sexual orientation, or trade-union membership. We do not ask for payment-card details on this website. Please do not send us any of these.

I.2 Our research programme

This section applies if you take part in our research, including the Goa AI Readiness Benchmark. It is a public statement of commitments we hold ourselves to, not boilerplate.

What we collect. Your name, role, employer, contact details and what you tell us in interviews. We also record publicly observable facts about the property or business — published rates, response times, website structure and similar — which we gather without needing your cooperation.

Our commitments.

  1. Findings are published only in aggregate and anonymised. No property and no

individual is identified in any published report without separate, written permission.

  1. Your individual results are confidential and are never shown to a competitor.

Your data belongs to the conversation we had, not to our sales pipeline.

  1. Every audited property receives its own results free and unconditionally,

whether or not it ever becomes a client, and whether or not it wants anything further from us.

  1. You may withdraw at any time, before or after publication, and we will remove

your data from the dataset. Where a finding has already been published in aggregate form and cannot be disentangled, we will tell you so plainly rather than imply otherwise.

  1. Participation is not conditional on buying anything. Declining to buy has no

effect on what you receive.

Legal basis. Consent, which you may withdraw at any time by writing to the Grievance Officer. Where we record only publicly available information about a business, we rely on legitimate interests in conducting research.

I.3 Cookies and similar technologies

Strictly necessary cookies keep the site working. They cannot be switched off and are set without consent, as the law permits.

Analytics cookies (Google Analytics 4, loaded through Google Tag Manager) tell us which pages and papers are read. What happens depends on where you are, and we would rather state that plainly than imply a single rule:

We use Google Consent Mode, so your choice is passed to Google directly and applies from the moment you make it. Withdrawing consent is as easy as giving it, and takes effect immediately.

Our research papers set no analytics cookies at all. On research.holycowstudios.in, wherever you are in the world, measurement is cookieless: we can see that a page was viewed and roughly where from, but nothing is stored on your device, nothing identifies you, and one visit cannot be linked to another.

We use no advertising, marketing or profiling cookies anywhere, in any region. Advertising storage is switched off by default and we have never switched it on.

Your browser can also block or delete cookies. Doing so may stop parts of the site working.

I.4 Who we share it with

We share personal data only with providers who process it on our instructions, and only as far as they need it to do their job.

We may also disclose personal data where we are legally required to — to a court, regulator or law-enforcement authority acting under proper authority — or to establish or defend legal claims. If we are ever compelled to disclose your data, we will tell you unless we are legally prohibited from doing so.

I.5 International transfers

We are based in India. Some providers above are in the United States or the European Union, so your personal data may be transferred outside your country.

Where data protected by the GDPR or UK GDPR is transferred outside the UK or EEA, we rely on the European Commission’s Standard Contractual Clauses, or on an adequacy decision where one applies. You may request a copy of the safeguards we rely on by writing to the Grievance Officer.

I.6 How long we keep it

When a period ends we delete the data or irreversibly anonymise it.

Part II — Data we process on behalf of clients

When we build, run or support an automation, an AI system or an IT service for a client, personal data may pass through it — the client’s customers, guests, staff or suppliers.

For that data, the client is the controller and we are the processor. We act only on the client’s documented instructions, under a written contract or data processing agreement.

What that means in practice:

  • We do not decide what that data is used for. The client does.

  • We do not use it for our own purposes — not for research, not for marketing,

not for training any AI model, not for our benchmarks or case studies. Where we publish a case study, it is agreed in writing with the client first and contains no personal data.

  • We keep it only as long as the engagement requires, then return or delete it as

the client instructs.

  • We apply the same security measures described in §III.3.

  • If we engage a sub-processor, we do so only where the client’s contract permits

and under equivalent obligations.

If you are a customer of one of our clients and want to exercise rights over your data, please contact that organisation — they are the controller and hold the relationship with you. If you contact us instead, we will pass your request on promptly and tell you we have done so, but we cannot act on it directly without the client’s instruction. This is a legal constraint, not an unwillingness to help.

Part III — General

III.1 Your rights

Wherever you live, you may ask us to:

  • Tell you what personal data we hold about you, and give you a copy

  • Correct anything inaccurate or incomplete

  • Delete it, where there is no overriding reason for us to keep it

  • Restrict or object to how we use it

  • Port it to another provider in a machine-readable form

  • Withdraw consent at any time, without affecting anything done before you

withdrew it

Depending on where you live you may also have the right to:

  • India (DPDP Act 2023): nominate another person to exercise these rights on

your behalf if you die or become incapacitated; use our grievance redressal process before approaching the Data Protection Board of India; and, where we make consent available through a registered Consent Manager, to give, manage, review and withdraw your consent through that Consent Manager

  • EEA / UK (GDPR): complain to your data protection authority

  • California (CCPA/CPRA): know, delete, correct, and opt out of sale or sharing —

we do not sell or share personal data, so there is nothing to opt out of — and not be discriminated against for exercising these rights

How to exercise them. Write to gaurav.hooda@holycowstudios.in. We respond within 30 days. We may ask you to confirm your identity first — not to obstruct you, but because handing your data to someone impersonating you would be a worse failure than a delay. Exercising these rights is free.

III.2 Automated decision-making

We do not make decisions about you by automated means that produce legal effects or similarly significant effects.

We advise clients on artificial intelligence, and we use AI tools in preparing our own research and written material. Those tools are not used to make decisions about individuals, and personal data you give us is not used to train any third-party AI model.

III.3 Security

We use HTTPS across all our sites, restrict access to personal data to people who need it, and choose providers who maintain recognised security practices. These are reasonable security safeguards appropriate to the data we hold; they are not a guarantee.

No system is perfectly secure, and anyone who tells you otherwise is selling something. If we become aware of a breach affecting your personal data, we will notify you and the relevant authority as the law requires — under the DPDP Act, the Data Protection Board of India, and under the GDPR, within 72 hours where the breach is likely to result in a risk to your rights.

III.4 Children

Our services are for businesses and are not directed at children. Under the DPDP Act, a child is anyone under 18. We do not knowingly collect personal data from anyone under 18, we do not knowingly track or behaviourally monitor children, and we do not direct advertising at them. If you believe a child has given us personal data, tell us and we will delete it.

III.5 Other websites, widgets and anything you post publicly

Links. Our sites link to other organisations’ websites. We do not control them and are not responsible for their content or their privacy practices. Check their policies before giving them your data.

Social media links and widgets. Where our site links to or embeds LinkedIn, WhatsApp, X or similar, your interaction with those is governed by that company’s privacy policy, not ours.

Anything you post publicly. If you post a comment, review or message in a public place — including our social media pages — it can be read, copied and used by others. We are not responsible for personal information you choose to disclose publicly.

III.6 Do Not Track and Global Privacy Control

There is no single agreed standard for “Do Not Track” browser signals, and we do not currently respond to them. We do honour the Cookie Settings choice you make on this site, which is the control that actually governs what we collect.

III.7 Business transfers

If our business is sold or reorganised, personal data may transfer to the acquirer, who will remain bound by this policy until you are told otherwise.

III.8 Language

This policy is published in English. On request to the Grievance Officer, we will provide it in any language listed in the Eighth Schedule to the Constitution of India.

III.9 Changes to this policy

We may update this policy. The effective date at the top always shows the current version. If we make a change that materially affects your rights, we will say so prominently on this page and notify subscribers by email. We will not apply a materially different use of data you have already given us without asking you again.

III.10 Governing law

This policy is governed by the laws of India, and the courts at Karnal, Haryana have jurisdiction. This does not remove any right you have to bring a claim, or complain to a regulator, in the country where you live.

III.11 Complaints

Please raise any concern with our Grievance Officer first — we would rather fix it than have you escalate.

If you are not satisfied, you may complain to:

  • India: the Data Protection Board of India

  • EEA: the supervisory authority in your country of residence or work

  • UK: the Information Commissioner’s Office

III.12 Contact

Gaurav Hooda, Grievance Officer Holy Cow Studios Private Limited gaurav.hooda@holycowstudios.in Sector 32 Park 3, First Floor, House No 13, Unnamed Road, Sector 32, Karnal, Haryana 132001, India +91 9311421200

·

Legal name: Holy Cow Studios Private Limited

CIN: U72900DL2021PTC378100

Registered office: Sector 32 Park 3, First Floor, House No 13, Unnamed Road, Sector 32, Karnal, Haryana 132001, India

Operations: Next to Magsons Supercentre, Dayanand Bandodkar Marg, Miramar, Panaji, Goa 403001, India

Email: office@holycowstudios.in

Telephone: +91 9311421200

·

Name: Gaurav Hooda

Designation: Grievance Officer

Email: gaurav.hooda@holycowstudios.in, or office@holycowstudios.in

Postal address: Sector 32 Park 3, First Floor, House No 13, Unnamed Road, Sector 32, Karnal, Haryana 132001, India

Working hours: Monday to Friday, 10:00–18:00 IST, excluding public holidays

· Part I — data we control · Part II — data we process for a client

Whose data: Website visitors, enquirers, subscribers, research participants Our client’s customers, staff or contacts

Our role: Data Fiduciary / controller — we decide why and how Data Processor — we act only on the client’s documented instructions

Who you ask about your rights: Us The client, who is the controller. We will pass on any request we receive

What · When · Why · Legal basis (GDPR)

Name, email, phone, message: You submit the contact form To answer you Legitimate interests / steps prior to a contract

Email address: You subscribe to updates To send you research and updates Consent

Name, email, meeting details: You book a call To hold the meeting Steps prior to a contract

Correspondence and notes: You contact us To maintain a record of our dealings Legitimate interests

Where you are · What we do

European Economic Area and the United Kingdom: Analytics are off until you accept. Nothing is stored on your device before you choose

Everywhere else, including India: Analytics are on by default. You can switch them off at any time using Cookie Settings in the footer

Provider · What they do · Where

Framer B.V.: Hosts and serves this website Netherlands / EU

Google LLC: Google Analytics 4, Google Tag Manager, Google Fonts United States

Cal.com, Inc.: Meeting scheduling United States

Hostinger International Ltd: Email, and hosting for research.holycowstudios.in Lithuania / EU

Data · Retention

Contact-form enquiries that do not become client relationships: 24 months from last contact

Newsletter subscribers: Until you unsubscribe, plus 12 months

Client records: 8 years after the engagement ends, for tax and statutory purposes

Research programme data: Until the study is published, plus 36 months, to allow findings to be checked

Website analytics: 14 months